Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).(Citation: TechNet Remote Desktop Services)
Adversaries may connect to a remote system over RDP/RDS to expand access if the service is enabled and allows access to accounts with known credentials. Adversaries will likely use Credential Access techniques to acquire credentials to use with RDP. Adversaries may also use RDP in conjunction with the Accessibility Features or Terminal Services DLL for Persistence.(Citation: Alperovitch Malware)
View in MITRE ATT&CK®| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Adversaries use RDP for lateral movement into privileged systems. Administrative enclave ACLs restrict RDP to explicitly authorized source and destination relationships, directly preventing arbitrary RDP access into or through the enclave.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Adversaries use RDP for remote access or lateral movement into enterprise systems. RDP is inaccessible directly from external networks and reachable remotely only after authenticated VPN access through approved paths, directly preventing unauthenticated external RDP connectivity.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Adversaries use RDP for remote access and lateral movement between systems. Segmentation and inter-zone ACLs permit RDP only across approved administrative paths, directly preventing unauthorized RDP connectivity between network zones.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Remote Desktop access can be restricted through centrally managed authorization controls so that remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Using role-based access control (RBAC) to limit Remote Desktop Users group membership and Remote Desktop Protocol (RDP) permissions to users with a legitimate need can help prevent adversaries from using RDP for lateral movement.
References
|
| CIS-6.4 | Require MFA for Remote Network Access | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Enabling multi-factor authentication for remote logins helps minimize the adversary's ability to leverage stolen credentials.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Disabling Remote Desktop Services where RDP is not operationally required prevents adversaries from connecting through that service.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Secure RDP configuration, gateways, TLS, and restricted administrative access reduce interception and direct exposure. RDP remains usable by an adversary who possesses authorized credentials or an active session.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Restricting TCP 3389 to approved management sources directly prevents unauthorized RDP connections and reduces RDP-based lateral movement.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Restricting TCP 3389 to authorized management hosts directly limits unauthorized RDP access to servers.
References
|
| CIS-16.8 | Separate Production and Non-Production Systems | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Production/non-production segmentation can restrict RDP to explicitly approved administrative paths and block ordinary cross-environment RDP connectivity.
References
|